Information Disclosure in Eclipse BIRT Due to Host Header Manipulation
CVE-2023-0100
What is CVE-2023-0100?
Eclipse BIRT allows for the retrieval of reports using an absolute HTTP path due to a misconfigured default setting. Specifically, if the HTTP Host header matches the value specified in the __report parameter, reports can be accessed without proper authorization. This occurs most notably in environments lacking appropriate virtual host configurations, such as default setups in Apache Tomcat. The issue was identified and resolved in Eclipse BIRT version 4.13, ensuring that such unauthorized access cannot be exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Eclipse BIRT (Business Intelligence Reporting Tool) 2.6.2
Eclipse BIRT (Business Intelligence Reporting Tool) < 4.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
